CVE-2014-2955

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
14/07/2014
Last modified:
12/04/2025

Description

Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:raritan:px:*:*:*:*:*:*:*:* 1.5.8 (including)
cpe:2.3:o:raritan:px:1.0:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.0.4:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.1:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.1.6:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.2:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.2.5:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.2.7:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.3:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.3.1:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.3.5:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.4.1:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.5:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.5.4:*:*:*:*:*:*:*
cpe:2.3:o:raritan:px:1.5.7:*:*:*:*:*:*:*